Phoenix Cyber is looking for a Threat Intelligence Analyst, with Operational Technology (OT) focus, to join our client delivery team.
Job Description:
- Collects, reviews, and identifies cybersecurity threat intelligence from open source and intelligence reporting to analyze and provide actionable threat reporting and briefings for cybersecurity analysts.
- Provides support to content developers and cybersecurity engineers in identifying gaps in protection and detection of systems.
- Reviews log and network events and alerts related to systems for signs of attack or Advanced Persistent Threats.
- Performs root cause analysis and supports remediation efforts for incidents related to Operational Technology cybersecurity incidents.
- Acts as the Subject Matter Expert on OT cybersecurity related issues.
- Minimum 6 years of relevant IT experience
- Minimum 2 years of hands-on experience analyzing, securing, or threat-modeling Operational Technology (OT), Industrial Control Systems (ICS), or SCADA environments (Experience limited to enterprise IT security will not satisfy this requirement.)
- Working understanding of common industrial communication protocols and lower-level control architecture.
- Demonstrated experience applying ATT&CK for ICS, SPARTA, or Cyber Kill Chain for ICS to dissect adversary campaigns and analyze cyber-physical attack paths.
- Understanding of the NIST Framework
- Understanding of threats and vulnerabilities in OT environments.
- Must have an active Top Secret Security Clearance
Phoenix Cyber is a national provider of cybersecurity engineering services, operations services, sustainment services and managed security services to organizations determined to strengthen their security posture and enhance the processes and technology used by their security operations team.
Phoenix Cyber is an equal opportunity employer and complies with Executive Order 11246, Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veteran's Readjustment Assistance Act (VEVRAA), all amendments to these regulations, and applicable executive orders, federal, and state regulations. Applicants are considered without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, and/or veteran status.
Phoenix Cyber participates in E-Verify to confirm the employment eligibility of all newly-hired employees. To learn more about E-Verify, including your rights and responsibilities, go to https://www.e-verify.gov/
Skills Required
- Minimum 6 years of relevant IT experience
- Minimum 2 years of hands-on experience analyzing, securing, or threat-modeling OT, ICS, or SCADA environments
- Working understanding of common industrial communication protocols and lower-level control architecture
- Experience applying ATT&CK for ICS, SPARTA, or Cyber Kill Chain for ICS
- Understanding of the NIST Framework
- Understanding of threats and vulnerabilities in OT environments
- Active Top Secret security clearance
What We Do
Phoenix Cyber is a national provider of cybersecurity engineering, operations, and sustainment services to enterprise and government organizations determined to strengthen their security posture and enhance the processes and technology used by their security operations center. Our team comprises senior cybersecurity consultants and engineers with expertise in architecting results-oriented, cybersecurity frameworks; and the operational processes to ensure accurate incident detection, enrichment, and response. Our unique blend of security automation, orchestration, and proven best practices differentiates Phoenix-architected solutions from traditional cybersecurity services. Cybersecurity Services - Security Engineering (plan, architect, design, implement, integrate, document, and optimize) - Security Operations (identify, protect, detect, respond, recover processes and best practices) - Sustainment Services (manage, maintain, update, upgrade, optimize, support) - Federal Government Services (contracts with U.S. Navy, FAA, DLA, and CIO-SP3) Capabilities - Data Protection - Endpoint Security - Network Security - Perimeter Security - Phishing Detection and Response - Security Orchestration, Automation, and Response (SOAR) - SIEM - Threat Intelligence - Threat Hunting Security Tools AWS, Microsoft, Swimlane, UiPath









